Justice K.S.Puttaswamy(Retd) vs Union Of India on 26 September, 2018
ASAs are not permitted to maintain any logs related to IP address of the device, GPS
coordinates of the device etc. ASAs are mandated to maintain logs as per Regulation
20 of the Authentication Regulations:
(i) identity of the requesting entity;
(ii) parameters of authentication request submitted; and
(iii) parameters received as authentication response.
Provided that no Aadhaar number, PID information, device identity related data and
e-KYC response data, where applicable, shall be retained.
(11) Referring to slide/page 7 and 14, please confirm that traceability features enable UIDAI to track
the specific device and its location from where each and every authentication takes place.
Ans.: UIDAI gets the AUA code, ASA code, unique device code, registered device code used for
authentication. UIDAI does not get any information related to the IP address or the GPS location
from where authentication is performed as these parameters are not part of authentication (v2.0)
and e-KYC (v2.1) API UIDAI would only know from which device the authentication has happened,
through which AUA/ASA etc. This is what the slides meant by traceability. UIDAI does not receive
any information about at what location the authentication device is deployed, its IP address and its
operator and the purpose of authentication. Further, the UIDAI or any entity under its control is
statutorily barred from collecting, keeping or maintaining any information about the purpose of
authentication under Section 32(3) of the Aadhaar Act.
Summing up the Scheme:
55) The whole architecture of Aadhaar is devised to give unique identity to the citizens of this
country. No doubt, a person can have various documents on the basis of which that individual can
establish her identify. It may be in the form of a passport, Permanent Account Number (PAN) card,
ration card and so on. For the purpose of enrolment itself number of documents are prescribed
which an individual can produce on the basis of which Aadhaar card can be issued. Thus, such
documents, in a way, are also proof of identity. However, there is a fundamental difference between
the Aadhaar card as a mean of identity and other documents through which identity can be
established. Enrolment for Aadhaar card also requires giving of demographic information as well as
biometric information which is in the form of iris and fingerprints. This process eliminates any
chance of duplication. It is emphasised that an individual can manipulate the system by having
more than one or even number of PAN cards, passports, ration cards etc. When it comes to
obtaining Aadhaar card, there is no possibility of obtaining duplicate card. Once the biometric
information is stored and on that basis Aadhaar card is issued, it remains in the system with the
Authority. Wherever there would be a second attempt for enrolling for Aadhaar and for this purpose
same person gives his biometric information, it would immediately get matched with the same
biometric information already in the system and the second request would stand rejected. It is for
Indian Kanoon - http://indiankanoon.org/doc/127517806/
40